Application Gateway
Vendor:
First CVE: Jun 1, 2021 · Active for 5 years
7
Total CVEs
More Total CVEs than 83% of tracked products
1.4
Avg CVEs / Year
Higher CVE frequency than 56% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 21% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Application Gateway over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 1, 2021
5 years ago
Most Recent CVE
Jan 20, 2026
186 days ago
CVE Severity & Scoring
Application Gateway7 CVEs
14%
57%
14%
14%
All CVEs352,708 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (28.6%)
Network5 (71.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (57.1%)
Unknown0 (0.0%)
Required3 (42.9%)
Privileges Required
Low5 (71.4%)
High0 (0.0%)
None2 (28.6%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-28787CRITICAL IBM Security Verify Access 10.0.0 through 10.0.7 and IBM Application Gateway 20.01 through 24.03 could allow a remote attacker to obtain highly sensitive private information or cau | Apr 4, 2024 | 10.0 | 27 | NO | NO |
CVE-2021-20576HIGH IBM Security Verify Access 20.07 could allow a remote attacker to send a specially crafted HTTP GET request that could cause the application to crash. | Jun 1, 2021 | 7.5 | 25 | NO | NO |
CVE-2025-36397MEDIUM IBM Application Gateway 23.10 through 25.09 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim' | Jan 20, 2026 | 5.4 | 23 | NO | NO |
CVE-2022-22387MEDIUM IBM Application Gateway is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functiona | Sep 28, 2022 | 5.4 | 20 | NO | NO |
CVE-2025-36396MEDIUM IBM Application Gateway 23.10 through 25.09 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI | Jan 20, 2026 | 5.4 | 18 | NO | NO |
CVE-2024-45655MEDIUM IBM Application Gateway 19.12 through 24.09 could allow a local privileged user to perform unauthorized actions due to incorrect permissions assignment. | Jun 3, 2025 | 5.5 | 17 | NO | NO |
IBM Security Verify Access 20.07 allows web pages to be stored locally which can be read by another user on the system. X-Force ID: 199278. | Jun 1, 2021 | 3.3 | 15 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (7 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (7 CVEs).
Media Mentions
Signals from CVEs in this product scope (7 CVEs).
Top CNAs Publishing CVEs For Application Gateway
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.0 | 3 | 5.4 | 1.0% | 0 | 0 |